ISO 27001 Annex A Controls Explained

ISO 27001 Annex A controls grouped and explained

Annex A is the catalogue of 93 security controls published with ISO 27001. You select from it based on your risk assessment, and record every decision in the Statement of Applicability.

  • Glossary
  • Compliance

The short answer

Annex A of ISO/IEC 27001:2022 lists 93 controls across four groups: A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). Each is one line long. ISO 27002 is the companion document explaining how to implement them.

How Annex A is numbered

Controls are referenced by group and number, so A.8.8 means the eighth control in the technological group. Auditors, questionnaires and compliance tools all use these references, so it is worth knowing which range covers what.

93 CONTROLS IN FOUR NUMBERED GROUPS A.5 Organisational A.5.1 to A.5.37 37 policies, suppliers A.8 Technological A.8.1 to A.8.34 34 access, crypto, logging A.7 Physical A.7.1 to A.7.14 14 facilities, equipment, disposal A.6 People A.6.1 to A.6.8 8 screening, training, offboarding
Swipe to see the full chart. A.5 and A.8 hold three quarters of Annex A between them, which is where most implementation effort goes.

The 11 controls added in 2022

The 2013 edition had 114 controls in 14 domains. The 2022 edition regrouped them into 93 and added eleven that did not exist when the previous version was written. If you are moving from the old edition, these are the gaps to close.

ReferenceControlWhy it was added
A.5.7Threat intelligenceDefence should reflect what attackers are currently doing
A.5.23Cloud services securityMost infrastructure is now someone else’s
A.5.30ICT readiness for continuityRecovery objectives have to be tested, not assumed
A.7.4Physical security monitoringDetection of physical intrusion, not just prevention
A.8.9Configuration managementMisconfiguration overtook exploits as a breach cause
A.8.10Information deletionPrivacy laws now require data to be removed on request
A.8.11Data maskingLimits exposure in non-production and analytics
A.8.12Data leakage preventionInsider and accidental loss became a primary risk
A.8.16Monitoring activitiesLogging alone is not detection
A.8.23Web filteringBlocks a common malware delivery path
A.8.28Secure codingSecurity moved earlier into development

Which controls apply to you

Controls follow risk. You assess risks, decide how to treat each one, then check those treatments against Annex A to confirm nothing obvious was missed. Every control is then marked applicable or not in the Statement of Applicability, with a reason.

ExclusionDefensible when
A.7 physical controls, in partFully remote, no offices or data centres in the certified scope
A.8.28 secure codingNo software is developed in house within scope
A.7.12 cabling securityNo owned network infrastructure, everything cloud hosted
A.8.8 technical vulnerability managementAlmost never. Expect a challenge if you exclude this

Applicable is not the same as implemented

The SoA has two separate columns for a reason. A control can be applicable and still be in progress. Marking everything implemented when it is not is the fastest route to a Stage 2 nonconformity.

Controls a SaaS startup always needs

Scope varies, but a cloud software company with customer data will be asked about these in almost every audit and every security questionnaire.

ReferenceControlWhat the auditor looks for
A.5.1Policies for information securityApproved, dated, communicated, reviewed
A.5.15Access controlLeast privilege, joiner and leaver records
A.5.23Cloud services securityHow you assess and monitor your providers
A.5.24Incident management planningA tested plan with named responders
A.6.3Awareness and trainingCompletion records, not just a deck
A.8.5Secure authenticationMFA enforced, exceptions documented
A.8.8Technical vulnerability managementScanning, remediation timeframes, evidence of closure
A.8.13Information backupBackups taken, encrypted, and restore tested
A.8.15LoggingWhat is logged, retained how long, reviewed by whom
A.8.24Use of cryptographyA key management policy, not just encryption switched on

Which controls Osto covers

Most of A.8 is deployed rather than written. Osto covers secure authentication (A.8.5), malware protection (A.8.7), technical vulnerability management (A.8.8), configuration management (A.8.9), data leakage prevention (A.8.12), logging and monitoring (A.8.15 and A.8.16), cryptography in transit (A.8.24) and web filtering (A.8.23), along with cloud services security (A.5.23), with evidence mapped to each reference. The A.6 people controls and most of A.7 stay with you, because they describe how your organisation behaves rather than how your systems are configured.

Free security assessment

Most of A.8 is deployed, not written

Osto runs the technological controls directly, from secure authentication to logging, with evidence mapped to each Annex A reference.

Get a free security assessment Book a platform walkthrough

Controls that actually run · Mapped evidence · One platform, everything

Frequently asked questions

How many controls are in Annex A?

Ninety-three in ISO/IEC 27001:2022, split into A.5 organisational (37), A.6 people (8), A.7 physical (14) and A.8 technological (34). The 2013 edition had 114 controls across 14 domains.

Are all Annex A controls mandatory?

No. Annex A is a reference catalogue. Controls are selected according to your risk assessment, and exclusions are permitted provided each is justified in the Statement of Applicability. Excluding a control because it is inconvenient is not acceptable.

What is the difference between Annex A and ISO 27002?

Annex A lists each control in a single line. ISO 27002 is a separate guidance document explaining the purpose of each control and how to implement it. Certification is against ISO 27001; there is no certification against ISO 27002.

What are the control attributes introduced in 2022?

Five optional tags on each control: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They let large programmes filter and group the catalogue. Small teams generally do not use them.

Which Annex A controls are hardest for startups?

Usually the ones needing sustained records rather than a one-time setup: A.6.3 awareness training with completion evidence, A.8.8 vulnerability management with remediation timeframes met, and A.8.13 backup with a tested restore. Auditors ask for history on all three.